I think you need to check System: Advanced: Miscellaneous, "Skip rules when gateway is down":

Quote

By default, when a rule has a specific gateway set, and this gateway is down, rule is created and traffic is sent to default gateway.This option overrides that behavior and the rule is not created when gateway is down

pfSense is being nice to you, and making a rule to send your VPN traffic out the default gateway.Then, IMHO, you will still need a block rule, after the rule feeding 192.168.0.111 to VPNI, and before the general allow all rule, that blocks traffic from source 192.168.0.111